Risk Management System
One governed enterprise risk register, one approved methodology and one audit trail.
The controlled record of an organisation’s enterprise risk: a register with a ten-state lifecycle, assessment against the organisation’s own matrices with a multidimensional consequence model, facilitated workshops at four depths, a control register that keeps design effectiveness apart from operating effectiveness, and reports frozen at the moment they are issued.
- 0
- Lifecycle states
- 0
- Workshop depths
- 0
- Organisation levels
- 0
- Loadable datasets

Unrated is not low. Untested is not effective.
RMS does not treat unassessed risks as low or untested controls as effective. Unrated risks and controls without effectiveness evidence remain explicitly visible so the reported position reflects the register that actually exists.
Unrated risks stay visible
A risk with no approved assessment is shown as unrated and drawn in the exposure bar rather than excluded from it. The distribution then describes the register that exists, not the subset somebody got round to scoring.
Control assurance is separate from control count
Not working, working but not as designed, never assessed and open deficiencies are four different positions. A control register that reports only how many controls exist is reporting nothing.
Current and residual rating, and a dash where there is neither.
One register covers strategic, corporate, project, operational, engineering, financial, compliance, sustainability and cyber risk under a common approved methodology, with each risk carrying its own review date and current governance state.
Where a risk has no approved assessment the rating columns show a dash, because a blank and a low score are not the same statement.
- One methodologyEvery rating on the register comes from the same configurable matrix, so a rating means the same thing in a workshop and on the board pack.
- Consequence is multidimensionalSafety, environment, financial, reputational and other dimensions are assessed separately rather than collapsed into one judgement.
- Review is a date, not an intentionOverdue reviews are reported as a share of the register, because a register nobody reviews stops being a control.
A rating arrives when an assessment is approved.
Not when it is drafted, and not when somebody suggests one in a workshop. Until approval the risk counts on the register and carries no rating, which is exactly the uncomfortable state most registers are designed to hide.
A control is only a control if something has tested it.
The barrier model makes the question concrete: which controls stand between a cause and the event, which stand between the event and its consequences, and what evidence exists that each of them works.
Unrated is not low
A risk with no approved assessment is shown as unrated, never as low. It is drawn in the exposure bar rather than left out of it, so the picture describes the register that exists.
Design apart from operation
A control can be well designed and not working, or working but not as designed. RMS records those separately, because collapsing them is how a control register comes to say everything is effective.
Frozen at issue
A report is frozen when it is issued, so a board pack from March still shows what it showed in March even after the register has moved.
Corrected by appending
A record is corrected by appending rather than rewriting, and the audit log is append-only. What the register said at the time of a decision remains recoverable.
Operations, workshops, controls, knowledge and governance.
The application's own navigation. It runs standalone and does not duplicate what another application already masters. Every chip is a page.
Risk operations
The enterprise register through a ten-state lifecycle, assessed against configurable matrices with a multidimensional consequence model, with treatments, actions and reviews held against each risk.
- Risk Operations
- Risk register
- Assessments
- Treatments
- Reviews
Workshops
Follow a governed sequence of preparation, pre-pack, facilitated session, outcomes and review so workshop conclusions enter the enterprise register with their methodology and evidence intact.
- Workshops
- Preparation
- Pre-pack
- Session
- Outcomes
Controls
A control register where design effectiveness and operating effectiveness are recorded separately, with barrier models, deficiencies, and key risk, control and performance indicators against thresholds.
- Controls
- Control register
- BowTie
- Deficiencies
- Indicators
Risk knowledge
Reusable risk archetypes, a risk breakdown structure and risk packs, so a new project starts from what the organisation already knows about its own risks.
- Risk Knowledge
- Archetypes
- Risk breakdown structure
- Risk packs
- Knowledge Library
Governance
Appetite, tolerance and escalation thresholds, enterprise objectives, an eleven-level organisation structure and the calendar that carries the review cycle.
- Governance
- Appetite & tolerance
- Objectives
- Organisation
- Calendar
Analytics and reporting
Analytics, enterprise search and reports frozen at issue, with data management and integrations beneath them and an append-only audit log behind every change.
- Analytics
- Reports
- Enterprise Search
- Data management
- Integrations

The workshop conclusion lands in the register.
Facilitated workshops move from preparation through pre-pack, session, outcomes and review, with approved conclusions entered into the register. Issued board reports are retained as dated records so the position reported at a particular time remains reproducible.
- Reusable archetypes and a risk breakdown structure so a workshop starts from what is known
- Appetite, tolerance and escalation thresholds set once and applied consistently
- Reports frozen at issue, and corrections made by appending
Nothing is written until a preview has been accepted.
Import, bulk update, historical migration, export, templates and extract each state what they do and what they will not do. A historical migration brings dated records from a previous system in at the date they happened, and they cannot be changed afterwards.
- Twenty-six loadable datasets across every business area
- Templates carry the organisation’s own allowed values
- A complete extract of everything the organisation holds

More of what the application covers.
- Configurable matrices with a multidimensional consequence model
- Appetite, tolerance and escalation thresholds
- Eleven-level organisation structure
- Risk archetypes and a risk breakdown structure
- Key risk, control and performance indicators against thresholds
- Risk 360: assessments, controls, treatments, actions, reviews and timeline
- Validated import and export with preview before commit
- Append-only audit log behind every change
The enterprise authority, beside the domains that hold technical risk.
- PSMPSM: Process Safety Management SystemProcess safety holds the major-hazard barriers; RMS is the enterprise authority above them.
- HSEHSE: Health, Safety & Environment Management SystemOccupational incidents and job safety analyses reference the same control model.
- IMSIMS: Integrated Management SystemThe management system owns compliance; RMS does not duplicate what another application masters.
- ESGESG: Environmental, Social & Governance Management SystemSustainability risk is reported through ESG from the same governed register.
See RMS with one of your board risk registers.
Bring one risk register and one recent workshop. We will show the lifecycle it enters, the control assurance position behind it and the board report it would freeze.
